VU#234131: ViewSonic vCast media streaming service allows unauthenticated screen exfiltration and device compromise

2026-09-24T20:52:01Z•293a259af25af0a4a98c7c91f62a08bd7d968e93024ce2d8192ce3720bf7e6d3
CVE-2026-75907CVE-2026-82356CVE-2026-82987CVE-2026-82988CVE-2026-82989CVE-2026-86867CVE-2026-96775CVE-2026-96804CERT/CCMLflowOS-command-injectionRFID-cloningSecure-BootUEFIaccess-controlauthentication-bypassauthorization-bypasscruise-shipcryptographic-key-managementdevice-compromisehealthcaremultiple-vulnerabilitiespickle-deserializationprivilege-escalationremote-code-executionscreen-exfiltrationsmartboardsupply-chainunauthenticated-access

What happened

CERT/CC advisories describe multiple vulnerabilities disclosed September 16–24, 2026, including unauthenticated ViewSonic vCast screen capture and device compromise, RFID UID replay against Norwegian Cruise Line door controllers, non-rotatable Imprivata EAM RSA keys enabling appliance impersonation, cross-user conversation access in Kotaemon, Secure Boot bypass through vendor-signed UEFI Shell applications, root-level OS command injection in Dokploy, and MLflow pickle-deserialization control bypasses enabling code execution.

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
certcc_vulnotes
Record identifier
293a259af25af0a4a98c7c91f62a08bd7d968e93024ce2d8192ce3720bf7e6d3
Enrichment time
2026-09-24T20:52:01Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.